CVE-2024-48884 Information
Description
A improper limitation of a pathname to a restricted directory (‘path traversal’) in Fortinet FortiManager versions 7.6.0 through 7.6.1 7.4.1 through 7.4.3 FortiOS versions 7.6.0 7.4.0 through 7.4.4 7.2.5 through 7.2.9 7.0.0 through 7.0.15 6.4.0 through 6.4.15 FortiProxy 7.4.0 through 7.4.5 7.2.0 through 7.2.11 7.0.0 through 7.0.18 2.0.0 through 2.0.14 1.2.0 through 1.2.13 1.1.0 through 1.1.6 1.0.0 through 1.0.7 FortiManager Cloud versions 7.4.1 through 7.4.3 FortiRecorder versions 7.2.0 through 7.2.1 7.0.0 through 7.0.4 FortiVoice versions 7.0.0 through 7.0.4 6.4.0 through 6.4.9 6.0.0 through 6.0.12 FortiWeb 7.6.0 7.4.0 through 7.4.4 7.2.0 through 7.2.10 7.0.0 through 7.0.10 6.4.0 through 6.4.3 allows attacker to trigger an escalation of privilege via specially crafted packets.
Reference
https://fortiguard.fortinet.com/psirt/FG-IR-24-259
Share on: